INC Ransom
Ransomware-as-a-Service (RaaS) operation · Financial — ransomware and double extortion
Tactics, Techniques & Procedures (TTPs)
- Rust-based cross-platform encryptor: Windows and Linux/ESXi builds from a single codebase
- Updated Veeam DPAPI credential dumper: extracts Veeam backup credentials via Windows DPAPI abuse, modified to bypass AMSI and modern EDR products
- Initial access via exposed RDP, phishing, and VPN exploitation
- LOLBin lateral movement: RDP, PsExec, and WMI across domain environments
- Cobalt Strike for interactive operator access during extended dwell and exfiltration phase
- Rclone exfiltration to attacker-controlled cloud storage before encryption deployment
- Possible Osiris ransomware affiliate overlap: Poortry BYOVD driver-based EDR killer and code structural similarities observed
Known Targets
Analyst Notes
INC Ransom has been active since August 2023, reaching 830+ claimed victims by mid-2026 and placing fourth globally by victim count in Q1 2026. The NHS Scotland breach (March 2024) — 3TB of patient data including clinical records — established INC as willing to attack high-profile healthcare targets. The Veeam DPAPI credential dumper is INC's most operationally significant tool: it targets backup administrator credentials that organisations rely on for ransomware recovery, with an AMSI bypass to function against modern endpoint security. Possible Osiris ransomware affiliate overlap (Poortry BYOVD, code similarities) suggests shared tooling across related Eastern European groups.
Also Known As